Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Gizer. Viruses Information

Name: I-Worm.Gizer.
Category: Viruses
Description: Details
I-Worm.Gizer.c

Gizer is a worm virus spreading via the Internet as an attachment to infected emails - it appends itself to Zip archives.
The worm itself is a Windows PE EXE file about 8 KB in length and written in Assembly language.
Infected messages have the following characteristics:
From: Microsoft Critical Response Team
Subject: Urgent message for all Windows users
Body:

Dear Windows User, The Microsoft Security Experts have discovered a bug inside the Windows files that poses a security threat to all versions of Windows newer than Windows98 (including Windows98). Virus experts have reported that few known viruses have been identified using this exploit, but more are expected. A patch has been supplied with this email and will fix the security hole. **THIS MESSAGE WAS DELIVERED BY THE AUTHOR FROM ENERGY WORM !!!** Attachment name: patch.exe
The worm activates from infected email only when a user clicks on the attached file.
The worm does not install itself to the system and is not repeatedly activated. The only way to run the virus again is to double click the attached file.
When the worm is launched, it copies itself to the current folder under the name windows.tmp, and displays the following message:
Could not patch due to bad CRC!

Spreading: e-mail
To send infected messages the worm connects to the SMTP server specified as the default in Windows. Gizer then sends messages to all addresses found in the Windows address book (WAB database).
Spreading: archives
Gizer also searches for all files with the .ZIP extension on all hard drives and appends its copy to them.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word.Sinc
Trojan-Spy.HTML.Smitfraud.
Predator.113
Urfin.31
Win32.Hidra
TNSE famil
Trojan-Dropper.Win32.VB.i
Trojan.BAT.VS
Salamanca.120
Maximum.119


 


© 2006-2008 spyware32.com - Privacy Policy